Skip to content

Is Web Scraping Legal in 2026? US, EU and UK Rules for Lead Generation

September 5, 2026. The question "is web scraping legal" has two honest answers, and lead-generation teams usually hear only the first. The first is that in the United States, scraping publicly accessible pages is very unlikely to be a federal computer crime, a position the Ninth Circuit reached in 2022 and extended to AI shopping agents in August 2026. The second is that almost every scraping company that has been sued or fined since then lost on something other than the hacking statute: breach of a site's terms, fake accounts, the copyright anti-circumvention rule, or, in Europe, the duty to tell people you hold their data. The only European enforcement case squarely about scraping LinkedIn for B2B prospecting ended not with its 240,000 euro fine but with the vendor erasing a 160-million-contact database and stopping collection entirely. Here is where the law stands in the US, EU and UK, drawn from the opinions and decisions themselves.

United States: the CFAA is mostly closed, everything else is open

  1. Van Buren v. United States (Supreme Court, June 3, 2021). A person "exceeds authorized access" under the Computer Fraud and Abuse Act only by entering parts of a computer that are off-limits to them; it is a gates-up-or-down inquiry, and using access for a forbidden purpose does not count. The Court left open, in a footnote, whether the gates can be set by contracts and policies rather than only by code.
  2. hiQ Labs v. LinkedIn (Ninth Circuit, April 18, 2022). On remand the court held hiQ had raised serious questions that the CFAA does not reach scraping of public profiles: a public website has erected no gates to lift or lower. It was a likelihood ruling, and the opinion itself lists contract, trespass, copyright and misappropriation as claims that may still lie.
  3. hiQ v. LinkedIn, the ending (N.D. Cal., November 2022 and December 6, 2022). The district court found LinkedIn's User Agreement unambiguously prohibited hiQ's scraping and that hiQ had used crowd workers with fake accounts. The consent judgment that followed carried a $500,000 judgment, a stipulation that LinkedIn could establish CFAA liability based on hiQ's access to password-protected pages using fake accounts, and a permanent injunction against automated copying whether logged in or not. The company that won the famous appeal ended the case enjoined and paying.
  4. Meta v. Bright Data (N.D. Cal., January 23, 2024). Summary judgment for the scraper on breach of contract: Meta's terms govern "your use" of Facebook and Instagram, and Bright Data did not use them when it scraped public pages while logged out, so the terms reached only logged-in scraping. No CFAA claim was pleaded.
  5. X Corp. v. Bright Data (N.D. Cal., May 9, 2024). Dismissed. The access-based claims were threadbare, and the scraping-and-selling claims were preempted because X sought de facto copyright ownership over users' content and was happy to allow extraction so long as it was paid. The case settled on confidential terms in June 2025; no appellate ruling exists.
  6. Amazon v. Perplexity (Ninth Circuit, August 4, 2026). A preliminary injunction against Perplexity's shopping agent was vacated: when a user directs an agent to shop on Amazon, it is the user who accesses Amazon's computers, so Amazon was unlikely to prove access by Perplexity under the CFAA. The court noted in a footnote that Amazon may still regulate access through its terms of service.
  7. Reddit v. SerpApi and others (S.D.N.Y., July 31, 2026). The new front. According to the case summaries available, the court largely denied motions to dismiss and treated Google's JavaScript challenges and CAPTCHAs as a technological measure that effectively controls access under the DMCA's anti-circumvention rule, even for pages humans can read freely. Weeks earlier a Northern District of California judge reportedly dismissed Google's own DMCA claims against SerpApi where the scraped results contained no copyrighted content. Two courts, two answers, and the question of whether a CAPTCHA is an access control is now live.

The practical enforcement example for lead data is LinkedIn's January 2025 suit against Proxycurl, which alleged fake accounts and demanded deletion of data inferred or aggregated from LinkedIn; by the vendor's own account it settled and the product shut down in mid-2025.

European Union: the fine is not the punishment

Personal data scraped from public pages is still personal data. GDPR Article 6(1)(f) allows processing for legitimate interests subject to a balancing test, and Recital 47 says direct marketing may qualify. Article 14 is the rule scrapers break: when data is not obtained from the person, you must tell them who you are, why you hold it and where it came from, within one month or at the first communication, and the disproportionate-effort exception in Article 14(5)(b) is read narrowly. Poland's Supreme Administrative Court upheld that reading in 2023 in the Bisnode case, where a B2B data broker had argued that notifying sole traders by post was too expensive.

The CNIL's KASPR decision of December 2024 is the case every lead-gen team should read. KASPR sold a browser extension that exposed contact details of LinkedIn profiles a customer visited, feeding a database of about 160 million contacts used for prospecting and recruitment. The CNIL found breaches of Article 6, because collecting details of users who had restricted visibility to their connections exceeded reasonable expectations; of the retention principle, because a five-year clock reset at every job change; of Articles 12 and 14, because there was no notice until 2022 and then only an English-language email; and of Article 15, because access requests were answered with "publicly accessible sources". The fine was 240,000 euro with a six-month injunction. On March 4, 2026 the CNIL closed the injunction, recording that KASPR had chosen to erase its database and to cease all data collection on LinkedIn. The Dutch authority's 30.5 million euro fine against Clearview in September 2024 sits at the other end of the scale, for scraping faces rather than job titles, and the AI Act has since banned untargeted scraping of facial images outright. For non-personal data, the copyright directive's text and data mining exception applies only where the rightholder has not reserved its rights in a machine-readable way, which is why a robots.txt opt-out has legal weight in the EU even when no personal data is involved.

United Kingdom: jurisdiction restored, guidance pointed

The ICO fined Clearview 7.5 million pounds in May 2022; a tribunal overturned it in 2023 for lack of jurisdiction; the Upper Tribunal reversed that in October 2025 and sent the case back, with Clearview given permission in December 2025 to appeal further. The ICO's published position on scraping, framed around AI training, is that legitimate interests is the sole available lawful basis, that scrapers must show why other collection methods were unsuitable, and that many controllers are not meeting their basic transparency obligations under Article 14. The Data (Use and Access) Act 2025, fully in force since February 5, 2026, names direct marketing as an example of what may be a legitimate interest, but leaves the balancing test and the marketing-email rules intact.

Platform terms, quoted

Google Maps Platform Terms, last modified August 26, 2026, section 3.2.3: "Customer will not export, extract, or otherwise scrape Google Maps Content" for use outside the services, and no caching except as expressly permitted. Google's general Terms of Service prohibit automated access that violates machine-readable instructions such as robots.txt and list scraping content that does not belong to you as grounds for suspension. LinkedIn's User Agreement, as quoted by the court in 2022, bars software or robots used to access, scrape, crawl or spider the services, and later versions add copying information obtained through data aggregators or brokers.

What it means for operators

Stop asking whether scraping is legal and start asking four narrower questions. Are you logged in? Logged-out scraping of public pages has beaten CFAA and contract claims; logged-in scraping and fake accounts have lost every time. Are you circumventing a technical measure? A CAPTCHA or bot challenge is now, in at least one federal court, a DMCA access control, and that theory does not care whether the content is public. Is it personal data about people in the EU or UK? Then Article 14 applies to you within a month, whatever the vendor told you, and the KASPR outcome shows what the regulator actually wants: not a fine, the end of the collection. And whose terms did you accept? The Maps API terms bind API customers; the LinkedIn agreement binds account holders; both are contract claims that survive a CFAA win.

For a lead generation workflow this cashes out as a preference for sources that publish business data for reuse, such as company registers and official APIs, logged-out collection of genuinely public business listings, a notification process for any EU or UK individuals you enrich, and a hard rule against tools that rely on fake or borrowed accounts. Our scraping tools comparison, LinkedIn scrapers guide and Google Maps scrapers guide rank vendors partly on these lines, and when we build scraping into an automation for a client, the Article 14 notice is part of the pipeline, not an afterthought.

Want lead data collected in a way that survives an Article 14 request?

We design, build, and run it for you, integrated with the tools you already use. Free audit in 24 hours.

Get Your Free Audit

Frequently Asked Questions

Scraping publicly accessible pages is very unlikely to violate the Computer Fraud and Abuse Act. The Supreme Court's 2021 Van Buren decision limited the statute to accessing off-limits parts of a computer, the Ninth Circuit applied that to public LinkedIn profiles in hiQ v. LinkedIn in 2022, and in August 2026 it held that a user directing an AI agent, not the agent's developer, is the one accessing Amazon. Password-protected pages and fake accounts remain squarely inside the statute.

Yes, as a breach of contract, if you are bound by them. In November 2022 a federal court found LinkedIn's User Agreement unambiguously prohibited hiQ's scraping, and the case ended with a $500,000 judgment and a permanent injunction. In January 2024 a court held Meta's terms did not reach Bright Data's logged-out scraping because it never used the platforms. Whether you were logged in is the deciding fact.

In December 2024 the French regulator fined KASPR 240,000 euro for a browser extension that scraped LinkedIn contact details into a 160-million-contact prospecting database. It found breaches of lawfulness, retention, transparency and access rights, including collecting details of users who had restricted visibility and failing to notify people under Article 14. In March 2026 the CNIL closed its injunction after KASPR erased the database and stopped collecting from LinkedIn.

Yes. Article 14 applies whenever personal data is not obtained from the person, and a named business contact is personal data. You must tell the person who you are, why you hold the data, its source and their right to object, within one month or at the first communication. The disproportionate-effort exception is read narrowly; Poland's highest administrative court upheld a fine against a B2B data broker that relied on it.

Not under Google's terms. The Google Maps Platform Terms, last modified August 26, 2026, state that customers will not export, extract or otherwise scrape Google Maps Content for use outside the services and may not cache it except as permitted, and Google's general Terms of Service prohibit automated access that violates robots.txt. Business listing data also belongs to the business. The Places API is the licensed route.

In at least one federal court, yes. In Reddit v. SerpApi, decided in the Southern District of New York on July 31, 2026, the court reportedly treated Google's bot challenges and CAPTCHAs as a technological measure that effectively controls access under the DMCA's anti-circumvention provision, even for pages humans can read. A California court reportedly dismissed similar claims by Google where the scraped results contained no copyrighted content, so the question is unsettled.

Free Strategy Audit

Ready to put this to work?

Join 200+ businesses already scaling with AI and automation. Get your free audit and a custom roadmap within 48 hours.

Website & marketing performance analysis
AI & automation opportunity mapping
Custom growth roadmap with ROI estimates
Delivered within 48 hours, 100% free
200+
Clients served
48hr
Turnaround
100%
Free, no strings

Get Your Free Audit

Takes 30 seconds. No credit card required.

Prefer to chat?

WhatsApp us